Odoo
First CVE: Apr 9, 2019Active for: 7 years
34
CVEs Published
More CVEs Published than 50% of tracked CNAs
8.5
Avg CVEs / Year
More Avg CVEs / Year than 49% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Odoo as a CNA, 100.0% affect products that Odoo develops as a vendor.
100.0%
Self-reported: 34Third-party: 0
Of all the CVEs published that affect products developed by Odoo, 63.0% are self-published by Odoo as a CNA.
63.0%
37.0%
Self-published: 34Published by other CNAs: 20
Trends Over Time
The number and severity of CVEs published by Odoo over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2019
7 years ago
Most Recent CVE
Feb 25, 2025
514 days ago
Top CVEs
All CVEs published by Odoo as a CNA, regardless of affected vendor or product.
34 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26947MEDIUM Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a vi | Apr 25, 2023 | 6.1 | 33 | NO | YES |
CVE-2018-15640HIGH Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request. | Apr 9, 2019 | 8.8 | 31 | NO | NO |
CVE-2021-44547CRITICAL A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed arbitrary code, leading to privilege escalation. | Apr 25, 2023 | 9.1 | 28 | NO | NO |
CVE-2020-29396HIGH A sandboxing issue in Odoo Community 11.0 through 13.0 and Odoo Enterprise 11.0 through 13.0, when running with Python 3.6 or later, allows remote authenticated users to execute ar | Dec 22, 2020 | 8.8 | 28 | NO | NO |
CVE-2021-23186HIGH A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to access and modify database contents of other tenan | Apr 25, 2023 | 8.7 | 27 | NO | NO |
CVE-2021-23166HIGH A sandboxing issue in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows authenticated administrators to read and write local files on the server. | Apr 25, 2023 | 8.7 | 27 | NO | NO |
CVE-2018-15632CRITICAL Improper input validation in database creation logic in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier, allows remote attackers to initialize an empty databas | Dec 22, 2020 | 9.1 | 27 | NO | NO |
CVE-2021-45111HIGH Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows remote authenticated users to trigger the creation of demonstration data, inc | Apr 25, 2023 | 8.1 | 26 | NO | NO |
CVE-2019-11781HIGH Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, allows remote attackers to trick victims into modifying their | Dec 22, 2020 | 8.8 | 26 | NO | NO |
CVE-2021-23178HIGH Improper access control in Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier allows attackers to validate online payments with a tokenized payment method that be | Apr 25, 2023 | 7.5 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA34 CVEs
65%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network34 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None23 (67.6%)
Unknown0 (0.0%)
Required11 (32.4%)
Privileges Required
Low18 (52.9%)
High4 (11.8%)
None12 (35.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (34 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.9% of CVEs· 89th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Odoo as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Odoo as a CNA — matched by CVE ID, not by organization name.